Security.io Intelligence DeskThursday, 3 September 2026
Independent analysis
for security executives
The Security.io DailyThe Weekday Intelligence Edition
Free to readers
Supported by underwriters
Regulatory · Executive briefing

White House creates a federally controlled private cyber operations programme

A presidential memorandum creates a US programme through which vetted private companies may conduct surveillance and effects operations against foreign cyber-enabled criminal organisations under federal control.

RegulatorySecurity LeadershipEnterprise Risk
Why it is in today’s brief

The memorandum was signed inside the publication window and creates a new federal mechanism for government-controlled private cyber operations. The material change is policy authority and operating structure, not a completed operation. It warrants inclusion over another technical advisory because CISOs now need explicit legal, board and supplier-governance boundaries before requests, partnerships or participation discussions arrive.

Read first

The United States has created a framework for government-directed private cyber operations against designated foreign criminal organisations.

Act now

Brief the general counsel and board risk sponsor on the memorandum's controlled participation model.

Accountable owner

General Counsel and CISO, with executive-risk and board oversight

Decision horizon

This week: establish governance for approaches, information requests or participation proposals; monitor the 180-day implementation process.

AssessmentHigh confidence
Emerging riskWatch for implementing procedures that define eligibility, oversight, target approval, liability, information-sharing controls, operational safeguards and reporting expectations.

What happened

On 12 August 2026, the White House issued a presidential memorandum creating a federally controlled programme for private-sector cyber operations against foreign cyber-enabled transnational criminal organisations. The programme may authorise Participating Companies to conduct Cyber Surveillance Operations and Cyber Effects Operations under federal control and oversight. The National Coordination Center, operating through the Homeland Security Task Force, is directed to create and manage the programme with executive leadership from the Department of Justice and Department of Homeland Security.

Participating Companies may receive threat information from private entities and government bodies for the purpose of proposing responsive operations to the National Coordination Center. Participation is described as voluntary, and operations remain under US Government direction, control and authority. The text therefore establishes a controlled government programme rather than a general right for companies to conduct independent retaliation against suspected attackers.

In the memorandum, the programme’s executive directors must submit a status report within 180 days and annually thereafter. The cited White House documents did not publish a list of approved companies or operational targets. Independent reporting characterised the policy as a significant expansion of private participation in offensive cyber activity. Attribution posture: The memorandum addresses categories of foreign cyber-enabled transnational criminal organisations and does not attribute a specific incident or actor.

Why this matters now

The memorandum changes the policy boundary around private-sector offensive capability without granting ordinary enterprises unrestricted permission to retaliate. Security leaders may encounter new requests to share threat information, support vetted providers or assess participation. Those decisions engage legal authority, evidence handling, privacy, contractual restrictions, insurance, cross-border data transfer and operational-risk questions that cannot be delegated to a threat-intelligence team alone.

The immediate enterprise issue is governance, not capability acquisition. Companies that are not programme participants still need rules for responding to government or supplier requests connected to an operation. Organisations considering participation need stronger separation of duties, executive authorisation, target validation, auditability and incident-containment boundaries than normal defensive testing requires.

The decision for security leaders

Place programme participation and related information sharing under a joint CISO, general counsel and executive-risk decision. Defensive threat intelligence should not drift into operational support through informal analyst relationships.

Define what evidence may be shared, which jurisdictions and contracts constrain it, how personal data is minimised, and how chain of custody is preserved before any external engagement.

Require participating suppliers to disclose authority, scope, oversight and containment boundaries. A vendor’s programme status should not substitute for the organisation’s own legal and risk assessment.

Evidence of closure

  • An approved policy defines who may discuss or support government-directed cyber operations.
  • A legal memorandum records the organisation’s authority, restrictions and prohibited activities.
  • A data-sharing standard defines approved evidence, minimisation and chain-of-custody controls.
  • Supplier contracts document whether offensive cyber activity is permitted, excluded or subject to approval.

The Security.io assessment

The memorandum is authoritative and materially changes US policy, but implementation details remain incomplete. It creates a programme and governance mechanism; it does not establish that any private company has been approved or that any operation has begun. The cited White House documents did not publish a list of approved companies or operational targets.

Attribution posture: The memorandum addresses categories of foreign cyber-enabled transnational criminal organisations and does not attribute a specific incident or actor. Security.io therefore treats this as a governance development rather than evidence about a particular campaign, victim or criminal group.

The near-term CISO value is boundary setting. Enterprises should be prepared for new public-private operating models while retaining clear prohibitions on unilateral action, unapproved intelligence disclosure and supplier activity that could create legal, diplomatic or operational exposure.

Questions for the morning meeting

  • Does the organisation have an approved boundary for sharing threat intelligence that could support government-directed operations?
  • Who can authorise discussions about programme participation, and which board committee requires notification?
  • Can legal, privacy and security teams distinguish voluntary federal participation from independent corporate hack-back activity?

Related intelligence

Shared decision context